SSL Verification Bypassed
The server's SSL certificate could not be verified. The analysis was completed using insecure mode. Data may be less reliable.
Reason:
Expired Certificate - the server's certificate has expired
Open
Cached
·
just now
91/100
SECURITY SCORE
Certificate Information
Subject
CN=id.xplenty.com
Issuer
C=US, O=Let's Encrypt, CN=E8
Valid From
January 02, 2026
Valid Until
April 02, 2026
60 days
Public Key
ECDSA
256 bit
(P-256)
Adequate
Signature Algorithm
ECDSA-SHA384
SHA-256 Fingerprint
7A:6B:D8:9B:21:31:2E:BF:68:DA:0A:CB:30:17:5A:3F:B9:59:8D:8B:7A:49:D2:D4:E2:DF:3B:45:9E:D9:60:91
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Present
max-age=31536000
Content-Security-Policy
Basic
script-src; worker-src; frame-src; +4 more
script-src 'unsafe-eval' 'unsafe-inline' 'self' *.openai.com chatgpt.com *.donal-tobin.workers.dev *.immagnify.com www.google.com www.gstatic.com *.upvert.io *.upvertcdn.io *.liadm.com *.usbrowserspeed.com *.getwarmly.com *.datashopper.com *.hubspot.com *.sentry-cdn.com *.cloudflare.com *.googleapis.com *.apollo.io *.redditstatic.com *.gstatic.com *.wistia.com *.termly.io *.unifyintent.com *.calendly.com *.adroll.com *.whattime.co.kr *.amazonaws.com *.referralcandy.com *.doubleclick.net *.clearbitscripts.com *.arcade.software *.clarity.ms *.clearbitjs.com *.capterra.com *.facebook.net *.googletagmanager.com *.hs-scripts.com *.licdn.com *.woopra.com *.ads-twitter.com *.youtube.com *.hotjar.com *.hsforms.net *.hs-analytics.net *.hs-banner.com *.hsadspixel.net *.hscollectedforms.net *.bing.com *.google-analytics.com *.g2crowd.com *.autopilothq.com *.mxpnl.com *.chilipiper.com *.googleadservices.com *.clickcease.com *.intercomcdn.com *.intercom.io *.visualwebsiteoptimizer.com app.vwo.com cdn.pushcrew.com; worker-src 'self' blob:; frame-src www.google.com www.gstatic.com app.vwo.com whattime.co.kr calendly.com *.liadm.com *.adroll.com *.doubleclick.net *.youtube.com *.facebook.com *.hsforms.com *.chilipiper.com *.arcade.software *.googletagmanager.com *.visualwebsiteoptimizer.com; default-src https: wss: data: 'unsafe-inline' ; object-src 'none'; frame-ancestors 'none' ; media-src 'self' blob: https:
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Present
geolocation=()
Recommendations
- • Increase HSTS max-age to at least 1 year and add includeSubDomains
- • Improve CSP by adding more specific directives and removing 'unsafe-inline'
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
CAA Records (Certificate Authority Authorization)
CAA Records
Configured
(Restricts certificate issuance)
Current Issuer
Authorized
(Matches CAA policy)
Authorized CAs
Recommendations
- • Consider using critical flag (flags=128) for stricter CAA enforcement
- • Consider adding 'iodef' records to receive notifications about unauthorized certificate issuance attempts
- • Consider adding 'issuewild' records to control wildcard certificate issuance